You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Graph API获取用户信息时遇AADSTS50013签名验证错误

使用On-Behalf-Of流程调用Graph API时遇到AADSTS50013错误

我的Angular应用采用以下调用流程:
Angular应用 → 传递授权码 → 自定义API(生成access-token) → Graph API(用户接口)

错误信息:
发生一个或多个错误。(OnBehalfOfCredential身份验证失败: AADSTS50013: 断言签名验证失败。[原因 - 已找到密钥,但使用该密钥验证签名失败。客户端使用的密钥指纹: 'F8A23743D9CD47B6D1A1FXXXXXXA17A9B1D919EC', 找到的密钥 'Start=10/02/2022 18:06:49, End=10/02/2027 18:06:49']。跟踪ID: 1d326676-f8a5-4410-b4cf-SSS1a9b64800 关联ID: 79ca8aec-bb73-48f9-b0d2-XXXb4226e625 时间戳: 2023-03-10 10:22:27Z)

Azure中配置的应用权限范围:

"openid", "profile", "User.Read.All"

代码实现:

var tenantId= "tenantid";
var clientId= "clientid";
var clientSecret = "secret";

// using Azure.Identity;
var options = new OnBehalfOfCredentialOptions
{
    AuthorityHost = AzureAuthorityHosts.AzurePublicCloud
};

// 用于通过On-Behalf-Of流程交换的传入令牌
var oboToken = accessToken;

var onBehalfOfCredential = new OnBehalfOfCredential(tenantId, clientId, clientSecret, oboToken, options);

GraphServiceClient graphClient = new GraphServiceClient(onBehalfOfCredential, scopes);

var result = graphClient.Users.GetAsync((requestConfiguration) =>
{
    requestConfiguration.QueryParameters.Count = true;
    requestConfiguration.QueryParameters.Search = "\"displayName:rock\"";
    requestConfiguration.QueryParameters.Orderby = new string[] { "displayName" };
    requestConfiguration.QueryParameters.Select = new string[] { "id", "displayName", "mail" };
    requestConfiguration.Headers.Add("ConsistencyLevel", "eventual");

}).Result;

内容的提问来源于stack exchange,提问作者Mannan Bahelim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 19:42:49